145 lines
5.4 KiB
JSON
145 lines
5.4 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20181730",
|
|
"Version": "oval:org.altlinux.errata:def:20181730",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2018-1730: package `glusterfs3` update to version 3.12.9-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch c9f2"
|
|
],
|
|
"Products": [
|
|
"ALT SPWorkstation",
|
|
"ALT SPServer"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2018-1730",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-1730",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2021-04142",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2021-04142",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2018-1088",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-1088",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades glusterfs3 to version 3.12.9-alt1. \nSecurity Fix(es):\n\n * BDU:2021-04142: Уязвимость функции gluster_shared_storage платформы хранения для физических, виртуальных и облачных сред gluster, позволяющая нарушителю повысить свои привилегии\n\n * CVE-2018-1088: A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2018-05-17"
|
|
},
|
|
"Updated": {
|
|
"Date": "2018-05-17"
|
|
},
|
|
"BDUs": [
|
|
{
|
|
"ID": "BDU:2021-04142",
|
|
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
|
|
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-266",
|
|
"Href": "https://bdu.fstec.ru/vul/2021-04142",
|
|
"Impact": "High",
|
|
"Public": "20180418"
|
|
}
|
|
],
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2018-1088",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-266",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-1088",
|
|
"Impact": "High",
|
|
"Public": "20180418"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:spworkstation:8.4",
|
|
"cpe:/o:alt:spserver:8.4"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730001",
|
|
"Comment": "glusterfs3 is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730002",
|
|
"Comment": "glusterfs3-client is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730003",
|
|
"Comment": "glusterfs3-events is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730004",
|
|
"Comment": "glusterfs3-geo-replication is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730005",
|
|
"Comment": "glusterfs3-rdma is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730006",
|
|
"Comment": "glusterfs3-server is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730007",
|
|
"Comment": "glusterfs3-vim is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730008",
|
|
"Comment": "libglusterfs3 is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730009",
|
|
"Comment": "libglusterfs3-api is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730010",
|
|
"Comment": "libglusterfs3-api-devel is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730011",
|
|
"Comment": "libglusterfs3-devel is earlier than 0:3.12.9-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20181730012",
|
|
"Comment": "python-module-glusterfs3 is earlier than 0:3.12.9-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |